CVE-2026-94391: WordPress Ultimate FAQ plugin <= 2.4.14 - Cross Site Scripting (XSS) vulnerability
Published Sep 23, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.
Affected Software
1 affected component
WordPress Ultimate FAQ<=2.4.14
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ultimate FAQ pluginto a version that resolves this vulnerability.Fixed in 2.5.0
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which users need to be trusted for exploitation?
An attacker needs Contributor-level access to the WordPress site. User interaction is also required for the XSS payload to take effect.
2
Which plugin versions are affected?
Ultimate FAQ versions up to and including 2.4.14 are affected.
3
What is the potential impact of successful exploitation?
The vulnerability can affect confidentiality, integrity, and availability, each with low impact. Its scope is changed, meaning impact may extend beyond the vulnerable plugin's security authority.